TLS Compat Tester
Check client-server compatibility for TLS versions.
Last reviewed by the Radiatus Cloud team
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
Match what the client speaks to what the server offers
A TLS handshake only succeeds when the client and server share a protocol version and cipher. When they do not, the connection fails with an error that names neither cause. This tool helps you reason about client-server TLS compatibility: which versions a given combination can agree on, and where an old client or a hardened server leaves no common ground.
Why old versions being gone is a good thing that breaks old clients
TLS 1.0 and 1.1 are deprecated and disabled on modern servers because they have known weaknesses. That is correct, but it means a device or library that only speaks those versions can no longer connect at all. Understanding compatibility is about seeing both sides: a server that requires TLS 1.2 or 1.3 is secure, and simultaneously unreachable to a client stuck on 1.0. The fix is upgrading the client, not weakening the server.
A planning aid before you change a configuration
Before you disable an old protocol version on a server, it helps to know which clients will be cut off; before you deploy an old client, it helps to know which servers will refuse it. Thinking through the compatibility matrix in advance avoids the outage that comes from discovering it in production. The reasoning runs in your browser.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
- Port Exposure Explainer — Understand risks of specific open ports.
Frequently Asked Questions
Why does a TLS connection fail with no clear reason?
Usually because the client and server share no protocol version or cipher they both accept. The handshake aborts before agreeing on one, and the error rarely names the specific mismatch.
Why can an old device no longer connect to some sites?
Because those sites have disabled TLS 1.0 and 1.1, which are deprecated for security reasons. A device that only speaks those versions has nothing in common with the server.
Should I re-enable old TLS versions to fix compatibility?
No. Re-enabling deprecated versions reopens known weaknesses. The correct fix is upgrading the client to speak TLS 1.2 or 1.3.
What versions should a server offer today?
TLS 1.2 and 1.3. TLS 1.3 is preferred where both sides support it; 1.2 remains widely necessary for compatibility.
Does this tool connect to my server?
It helps you reason about which versions a client and server can agree on; the analysis runs in your browser.
Privacy & Security
Processed locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
Firewall Rule Risk
NetworkEvaluate firewall rules for over-permissive exposure.